From a cost perspective, Vanta + a Vanta-partnered auditor was less expensive that just an auditor (presumably because the information was organized so the auditor had to do less work to complete the audit).
The Vanta platform ends up being a place to put documents so the auditor can find them (which is more useful than you might think if you haven't done a SOC-2 audit). They offer several Vanta-developed continuous monitoring tools (e.g., endpoint configuration monitoring, AWS vulnerability monitoring), which are not as well developed as independent tools (e.g., Kandji, AWS Inspector) but are convenient for auditors documenting continuous compliance.
As I understand it, they are working towards being more of an integration center for independent tools, so Kandji/AWS Inspector information can flow into the Vanta system.
Paying someone to give me a list of problems isn't at all useful until we have nothing else to do. Appreciate there may be others out there without the same understanding of Infosec, but frankly that's a greater risk to companies without those resources.
A newer tool that I’ve heard great feedback on is Drata. They’re more focused on automation and continuous evidence collection.
As others have said above, the compliance part will be a by-product and will essentially fall in place modulo some extra documentation effort (which can be heavily borrowed from templates).
Vanta and StrikeGraph etc no doubt will make it more convenient to follow best practices and scaffold your continuous monitoring, but I see it as a nice to have, not a must have.
Though seeing the other comments that Vanta + audit being cheaper than audit alone is an interesting quality and may change the initial defensive rejection I have for receiving cold contact mail on non-public addresses (which means they also buy harvested data).